..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

Wednesday, 11 May 2016

Clikjacking in HootSuite, found by Ahsan Tahir





Hey, I found a clickjacking vulnerability in HootSuite.
Risk: Low
Steps to reproduce:
1. Make a new html file, code:

<html>
   <head>
     <title>Clickjack test page</title>
   </head>
   <body>
     <iframe src="https://site.com" width="500" height="500"></iframe>
   </body>
</html>

Instead of site.com, we have to enter the site, which we want to test!
They did not patched the bug, as they think that they don't have time to patch low impact bugs!

But, I was listed in their Hall of Fame!
Link: https://hootsuite.com/security/

Saturday, 23 April 2016

Stored XSS In World Beyblade Organization, Found by Ahsan Tahir


SITE: World Beyblade Organization
BUG: Stored XSS (cross-site-scripting)
SECURITY RISK: High
STATUS: Patched!


Reproduction Steps :

1- Login in to your account
2- Go to Your profile and  click on edit profile
3-  Now change tumblr and set it to cross site scripting payload "><img src=x onerror=prompt(/xss-by-ahsan/)>
4- Click update profile and go to your profile , pop up will be executed!
Proof Of Concept Screen Shot:


Proof Of Concept Video:


Saturday, 17 October 2015

A Free Cyber Security Training Company - Cybrary!

Hi Guys, Wassup ?
Ahsan is here to tell you something special, and this is ...

So you are wasting hours, finding free hacking/IT-Security courses? 
I have the answer, Cybrary!

Well, Cybrary provides IT-Security courses, Cyber Security
training, etc. Plus, you can also find jobs related to Cyber Security! (https://www.cybrary.it/cyber-security-jobs/) Moreover, you can get certificates for completing courses!


I am also a member of Cybrary, and would advise you to join it!

Visit Here: www.cybrary.it

Saturday, 10 October 2015

Free Download Backtrack 5r3 Full Version

History: The BackTrack allotment originated from the integration of two formerly competing allotment which focused on piercing testing: WHAX: a Slax-based Linux distribution developed by Mati Aharoni, a security consultant. Earlier versions of WHAX were called Whoppix[6] and were based on Knoppix. Auditor Security Collection: a Live CD based on Knoppix developed by Max Moser which included over 300 supplies organized in a user-friendly hierarchy. The overlap with Auditor and WHAX in intention and in their collection of tools partly led to the merger.

Tools: BackTrack provided users with easy access to a comprehensive and large mixture of security-related gear ranging from port scanners to Security Audit. Support for Live CD and Live USB appropriateness allowed exploiter to boot BackTrack directly from portable media without requiring installation, though permanent installation to hard disk and network was also an option. BackTrack included dozens well known security tools including: Metasploit for integration Wi-Fi drivers fostering monitor manner (rfmon mode) and packet injection Aircrack-ng Gerix Wifi Cracker Kismet Nmap Ophcrack Ettercap Wireshark (formerly known as Ethereal) BeEF (Browser Exploitation Framework) Hydra OWASP Mantra Security Framework, a collection of hacking tools, add-ons and manuscript based on Firefox Cisco OCS Mass Scanner, a very reliable and fast scanner for Cisco routers with telnet and enabling of a default password. A large assortment of exploits as well as more commonplace software such as browsers. BackTrack arranged clothes into 12 categories: Information gathering Vulnerability assessment Exploitation tools Privilege escalation Maintaining access Reverse engineering RFID tools Stress testing Forensics Reporting tools Services Miscellaneous!

Follow me on Facebook:
https://www.facebook.com/AhsanTahirAT
--------------------------------------------
Follow me on Twitter:
https://twitter.com/Mr_4h54n


[!] Backtrack 5r3 Download Here [!]

How to Verify your Facebook Page!

Hi guys!
Today I am going to tell you guys that how to verify your Facebook fan page!!

Just follow these steps :-

1. First login to the Facebook account, during which you created your Facebook page. And then click here.

2. Request a "Verified Badge Page can open".

3.  Then choose your fan page from the drop-down list.

4. Then attach a photograph of you ID.

5. If you have your official site, then you must add it.

6. Finally, click on send button.

You will receive a message indicating, than your request has been submitted, after 2-3 days Facebook will determine, if they found your page to be real then they are going to verify your page, and inform you via E-mail.

Kali Linux - Advanced Pentesting Tool (32-bit)


Kali Linux is an advanced pentesting tool ... It is used for professional hacking and security.
If you have any problem, plz ask in the comments ^_^
.:: DOWNLOAD HERE ::. 

Kali Linux - 64-bit


Kali Linux is an advanced pentesting tool ... It is used for professional hacking and security. If you have any problem, plz ask in the comments
 ---------------------------------------------------------------
 ^_^ .:: DOWNLOAD HERE ::.